Описание
An issue was discovered in ConnectWise Automate before 2021.5. A blind SQL injection vulnerability exists in core agent inventory communication that can enable an attacker to extract database information or administrative credentials from an instance via crafted monitor status responses.
Ссылки
- Permissions RequiredVendor Advisory
- Vendor Advisory
- Product
- Permissions RequiredVendor Advisory
- Vendor Advisory
- Product
Уязвимые конфигурации
Конфигурация 1Версия до 2021.5 (исключая)
cpe:2.3:a:connectwise:connectwise_automate:*:*:*:*:*:*:*:*
EPSS
Процентиль: 61%
0.00418
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-89
Связанные уязвимости
github
больше 3 лет назад
An issue was discovered in ConnectWise Automate before 2021.5. A blind SQL injection vulnerability exists in core agent inventory communication that can enable an attacker to extract database information or administrative credentials from an instance via crafted monitor status responses.
EPSS
Процентиль: 61%
0.00418
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-89